Skip to main content
Version: 4.42

macOS and iOS agent installation and deployment

Overview​

This guide provides comprehensive instructions for installing and uninstalling the Redtrust agent in macOS and iOS environments. This guide is intended for system administrators or anyone responsible for deploying and configuring Redtrust.

By the end of this guide, you will have installed the Redtrust agent and be able to set up the platform.

Before you start​

If you install Redtrust on macOS and want to use Firefox, make sure you have the RedtrustPKCS11Installer.pkg package. If you can’t find it on your system, contact the support team.

warning

Note that due to operating system limitations, the macOS and iOS agents are only compatible with local users, SAML, and OAuth. In addition, on these platforms you can't audit or limit URLs or processes.

The PKCS#11 module isn't available on iOS, so you can't use certificates in Firefox or in Java applications.

For details about what you can do with Redtrust on these platforms, see Redtrust on Mac, iPhone, and iPad.

info

Redtrust is only compatible with AutoFirma 1.8.4 or higher.

System requirements​

The Redtrust agent requires macOS 14 (Sonoma) or later, or iOS 16 or later. Redtrust supports ARM processors.

Step 1: Install the agent​

  1. Get the agent and install it:

Get the agent's DMG file from your Redtrust provider. Open it and drag Redtrust to the Applications folder.

Once installed, open the agent:

  1. Select Choose a custom config.
  2. Complete the form:
    • Primary Server: IP address or host name of your Redtrust server.
    • Secondary Server: IP address or host name of your secondary server. If you don't have one, repeat the primary server.
    • Client Id: Key shared with the server. You can find it in the admin console, in System > Unit > Information.
    • Default Domain: Required if the authentication mode is SAML 2.0 or OAuth 2.0. Type the value without quotes.
    • Authentication Mode: Local Users, SAML 2.0, or OAuth 2.0.
tip

To modify the parameters of an existing macOS agent, go to Redtrust Agent in the menu bar and select Settings. Enable Show config screen on restart, then close the window. When you restart Redtrust, the configuration screen will appear and you’ll be able to modify the parameters.

Step 2: Configure Firefox for Java applications​

To use your certificates in Firefox, as well as in Java applications that use its certificate store (for example, AutoFirma), you must load the PKCS#11 library in Firefox. This step applies to macOS only: the PKCS#11 module isn't available on iOS.

  1. Click the Redtrust agent in the taskbar and then click Connect. Log in with your credentials.
  2. Install the RedtrustPKCS11Installer.pkg package.
  3. Click the Firefox ☰ menu and navigate to Settings > Privacy & security.
  4. Go to Certificates and click Security devices.
  5. In the list of security devices, click Load.
    1. In Module name add RedtrustPKCS11
    2. In Module filename click Browse, navigate to /Library/Frameworks and select RedtrustPKCS11.dylib.
    3. Click Ok.
  6. Reload Firefox.

Step 3: Verify the installation​

Test the installation by uploading and using a certificate, as explained in the initial configuration tutorial.

Next steps​

Now that you've verified the installation, you can:

Was this page helpful?